RE: [security-services] NIST prohibits use of SAML assertions at LOA 4

From
Cahill, Conor P <>
Date
2008-06-27T21:13:15+00:00
ID
Thread
RE: [security-services] NIST prohibits use of SAML assertions at LOA 4
> Well, it's interpreted in light of the fact that browsers cannot
perform
> proof operations with SAML assertions. What they want is not PKI in
> general, but PKI between the relying party and the client. More than a
> bearer token, in other words. There's plenty to be said for that
argument.

Yeah, but then they should be saying that they don't allow the browser
SSO
profile rather than disallowing the assertions. 

Conor